Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11206

Опубликовано: 16 мая 2018
Источник: redhat
CVSS3: 3.3

Описание

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

An out-of-bounds read flaw was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. This could allow a remote denial of service or information disclosure attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8hdf5Will not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)hdf5Will not fix
Red Hat OpenStack Platform 10 (Newton)hdf5Will not fix
Red Hat OpenStack Platform 12 (Pike)hdf5Will not fix
Red Hat OpenStack Platform 13 (Queens)hdf5Fix deferred
Red Hat OpenStack Platform 8 (Liberty)hdf5Will not fix
Red Hat OpenStack Platform 9 (Mitaka)hdf5Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1579960hdf5: out of bounds read in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 8.1
nvd
больше 7 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 8.1
debian
больше 7 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fi ...

CVSS3: 8.1
github
больше 3 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 8.1
fstec
больше 7 лет назад

Уязвимость функций H5O_fill_new_decode, H5O_fill_old_decode компонента H5Ofill.c библиотеки обработки HDF файлов HDF5, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

3.3 Low

CVSS3